PT-2024-27964 · Glpi+1 · Glpi+1

Published

2024-11-15

·

Updated

2026-05-06

·

CVE-2024-38370

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions 9.2.0 through 10.0.15
Description The issue allows unauthorized download of documents from the API without appropriate rights.
Recommendations Upgrade to version 10.0.16 to resolve the issue. As a temporary workaround, consider restricting access to the API endpoint to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-09879
CVE-2024-38370
GHSA-XRM2-M72W-W4X4

Affected Products

Glpi
Red Os